Policies

Everything Dovri publishes about how member data is handled and protected. Each policy is a page you can read here and a document you can download.

Privacy Policy

Version 1.0 · Effective 9 October 2026

What Dovri collects, why, who else sees it, how long it is kept and how to have it deleted. Written for members rather than reviewers, and the retention periods in it match the retention policy below.

Information Security Policy

Version 1.0 · Effective 9 October 2026 · Next review 9 October 2027

How security risks are identified, mitigated and monitored: risk register, access control, encryption, secure development and vulnerability remediation, third parties, logging, incident response, business continuity, and coordinated disclosure.

Access Control Policy

Version 1.0 · Effective 9 October 2026 · Next review 9 October 2027

Who may reach Dovri systems and member data, how that access is authenticated, and how it is changed, reviewed and removed. Covers named accounts, least privilege, multi-factor authentication, machine credentials and member authentication.

Data Retention and Disposal Policy

Version 1.0 · Effective 9 October 2026 · Next review 9 October 2027

How long each category of member data is kept, why, and how it is disposed of when the period ends. Includes the retention schedule, member deletion requests, legal holds and data minimisation.

Versions and questions

Each policy carries a version number and an effective date. When a policy changes, the version is raised and the effective date is updated; the page and the downloadable document are always the same text.

Security questions, vulnerability reports and partner diligence: security@joindovri.com. Anything else: support@joindovri.com. Machine-readable contact details are at /.well-known/security.txt.

Back to dovri